CVE-2026-22182Active Exploitation(gvectors / wpdiscuz)

MEDIUMCVSS 8.7 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch gvectors wpdiscuz systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificationType() function. Attackers can repeatedly call the wpdiscuz-ajax.php endpoint with arbitrary postId and comment_id parameters to flood subscribers with notifications, as the handler lacks nonce verification, authentication checks, and rate limiting.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862CWE-770

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wpdiscuz

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-16); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
wpdiscuz

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-08: 1Mentions · 2026-02-16: 3Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1PoC Mentioned / Linked · 2026-02-08: 1Active Exploitation · 2026-02-16: 2Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-16: 2Technical Details · 2026-03-13: 102-0802-1603-1303-14
Signal classification4 categories
Active Exploitation
233.3%
Disclosure
233.3%
PoC
116.7%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-081
PoC1
2026-02-163
Active Exploitation2General1
2026-03-131
Disclosure1
2026-03-141
Disclosure1
Full discourse6 posts
  • DarkShadow@darkshadow2bd
    PoC

    OpenCode RCE POC – Explain (CVE-2026-22182) For more join my BugBounty telegram channel 👉🏼 http://t.me/ShellSec ㅤ https://t.co/uIRzCUsyJQ

    Post summary

    The post references a proof‑of‑concept for CVE‑2026‑22182, linking to additional information, but does not mention active exploitation, patches, or detailed technical data.

    227126311515.5K
    6.1K followersView on X
  • Divert@Divert_Security
    Active Exploitation

    CVE-2026-22182: OpenCode Unauth RCE. We detected and blocked exploit attempts in our customer environments starting 2/8/2026. Emerging threats mitigation is just one of the many benefits of counter-reconnaissance: Cyber Deception Reimagined. https://t.co/yDwEtUxcZO

    Post summary

    The tweet reports that exploit attempts for CVE-2026-22182, an unauthenticated RCE, were detected and blocked in customer environments, confirming active exploitation in the wild.

    1001067
    8 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20841 2 - CVE-2025-55177 3 - CVE-2026-1731 4 - CVE-2025-9961 5 - CVE-2026-22182 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVEs but provides no further technical, exploit, or mitigation details.

    00010150
    1.7K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-22182 - gVectors - wpDiscuz - https://www.redpacketsecurity.com/cve-alert-cve-2026-22182-gvectors-wpdiscuz/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-22182 #gvectors #wpdiscuz

    Post summary

    A CVE alert for CVE‑2026‑22182 affecting wpDiscuz’s gVectors component is shared with a link to a security blog, but no further exploitation details or remediation guidance are offered.

    00000100
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22182 wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the c… https://www.cve.org/CVERecord?id=CVE-2026-22182

    Post summary

    The text announces a DoS vulnerability in wpDiscuz versions before 7.6.47 that enables anonymous users to generate mass notification emails.

    00000114
    56.7K followersView on X
  • Soo Yoon | FailSafe Ecosystem@sooyoon_eth
    Active Exploitation

    @Divert_Security CVE-2026-22182 unauth RCE is nasty. good thing you caught it early with deception tech. exploit attempts starting 2/8 means this was actively being weaponized. patch immediately if you're running opencode

    Post summary

    CVE‑2026‑22182 is an unauthenticated RCE that is actively being weaponized with exploit attempts noted from 2/8, and the advisory urges immediate patching for users of OpenCode.

    0000065
    23.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgvectorswpdiscuz-wordpress-

Explore more